Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Trojan.Crossrider1.25262

Added to the Dr.Web virus database: 2015-04-09

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-10_user.job
  • <SYSTEM32>\tasks\uaxtfe
  • %WINDIR%\tasks\uaxtfe.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-4
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-4.job
  • <SYSTEM32>\tasks\temp_7eac1701-e601-484f-8f22-d2e4387e8d8f-6
  • %WINDIR%\tasks\temp_7eac1701-e601-484f-8f22-d2e4387e8d8f-6.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-6
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-6.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-7
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.job
  • <SYSTEM32>\tasks\temp_8057d7e2-a1f7-4357-b3b0-1e903d796636
  • %WINDIR%\tasks\temp_8057d7e2-a1f7-4357-b3b0-1e903d796636.job
  • <SYSTEM32>\tasks\8057d7e2-a1f7-4357-b3b0-1e903d796636
  • %WINDIR%\tasks\8057d7e2-a1f7-4357-b3b0-1e903d796636.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-11
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-11.job
  • <SYSTEM32>\tasks\vrlgqc
  • %WINDIR%\tasks\vrlgqc.job
  • <SYSTEM32>\tasks\globalupdateupdatetaskmachineua
  • %WINDIR%\tasks\globalupdateupdatetaskmachineua.job
  • <SYSTEM32>\tasks\globalupdateupdatetaskmachinecore
  • %WINDIR%\tasks\globalupdateupdatetaskmachinecore.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-3
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-3.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-10_user
  • %WINDIR%\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-1.job
  • <SYSTEM32>\tasks\7eac1701-e601-484f-8f22-d2e4387e8d8f-1
Sets the following service settings
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdate] 'Start' = '00000002'
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdate] 'ImagePath' = '%ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /svc'
  • [<HKLM>\System\CurrentControlSet\Services\globalUpdatem] 'ImagePath' = '%ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /medsvc'
Creates the following services
  • 'globalUpdate' %ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /svc
  • 'globalUpdatem' %ProgramFiles(x86)%\globalUpdate\Update\GoogleUpdate.exe /medsvc
Malicious functions
Terminates or attempts to terminate
the following user processes:
  • firefox.exe
Registers BHO
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171168}]
Modifies file system
Creates the following files
  • %TEMP%\nsg4bcf.tmp
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\220.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\262.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\246.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\315.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\289.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\260.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\263.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\14.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\104.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\9.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\292.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\273.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\195.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\7.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\231.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\4.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\281.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\242.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\91.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\16.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\93.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\221.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\286.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\123.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\119.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\179.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\64.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\options.xul
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\cad9ee6315fb631094c040794ce5e562.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\2a9219ee127acd7eb1825e3fda0c3894.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\3d29b5ddb55a1c5c83acb85a726b5cce.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\60480452bedf5d6be8bcfbf796ab5c5d.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\browser.xul
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\options.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\search_dialog.xul
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\ffcorefilesindex.txt
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\background.html
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\f2417e51287f39007ee36726f3150729.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\dialog.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\223.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\178.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\c8a72d8435fcbacd137bf754934a36ce.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\cb5811cb84cea47e05579271ab085791.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\usercode\background.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\usercode\extension.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\13.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\47.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\17.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\78.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\102.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\288.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\184.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\0ab797be2762ac8cbb0fa2e5e4c85b1a.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\7152d7f1e4b62dc34a54eda3a5d9ad98.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\cd1f4a10de708343030b0d4370a41def.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\268.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\260.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\288.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\286.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\281.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\280.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\278.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\277.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\273.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\271.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\263.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\262.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\289.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\315.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\335.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\250.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\249.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\246.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\242.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\232.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\231.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\223.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\184.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\180.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\179.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\251.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\226.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\335.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\dcdfc40b-fc6e-49c8-ab24-30d86c986bbd.dll
  • %ProgramFiles(x86)%\dd37181a-1f52-4c34-8f46-66acea3359f2\ee28567e-d0c7-4066-903a-feeaad56979c.dll
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\232.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\manifest.xml
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins.json
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome.manifest
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\defaults\preferences\prefs.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\locale\en-us\translations.dtd
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\install.rdf
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-4.exe
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f.xpi
  • %CommonProgramFiles(x86)%\dd37181a-1f52-4c34-8f46-66acea3359f2.dll
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\extensiondata\plugins\180.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\4.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\78.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.exe
  • %CommonProgramFiles(x86)%\6de719af-7d2a-4483-9928-ee7167bf783b.dll
  • %ProgramFiles(x86)%\dd37181a-1f52-4c34-8f46-66acea3359f2\fd1d7e4a-8af9-4bfc-8351-12cb64ae39d8.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\3e21f702-57c7-4f17-ba95-6ef6f69d19ab.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-6.exe
  • %TEMP%\nsb4bff.tmp\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.dll
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\usercode\extension.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\usercode\background.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\93.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\91.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-64.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\goopdateres_en.dll
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\565b7f0a47be8edeeb890796b2e2e911.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\292.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\242.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\289.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\288.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\286.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\281.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\273.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\269.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\263.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\262.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\260.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\246.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\315.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\3.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\17.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\226.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\223.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\221.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\220.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\2.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\195.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\184.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\180.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\179.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\178.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\231.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\232.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\35.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\14.js
  • %TEMP%\nsb4bff.tmp\7eac1701-e601-484f-8f22-d2e4387e8d8f-1.dll
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\usercode\extension.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\usercode\background.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\94.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\93.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\91.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\9.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\78.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\7.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\64.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\335.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\hdtubev1.6v01.12-bho.dll
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\47.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\44.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\43.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\42.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\41.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\40.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\4.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\39.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\38.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\37.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\36.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\46.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\45.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\13.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\123.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\79967c7ef212a304803cf28d6fc4f5eb.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\eea0c983bd63828cd21bd75d74c9ef6a.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\e8ef05cb1fbc7b5bf283c89bc9879391.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\71a200c7798e7153941641ac2a756a53.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\4d4068844c5ad6c29bd523d94c03710b.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\ae0dc5e41350f94b6c1f2c42ec16bc45.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\b8ed3106502b8d14f12e8f6d8d05bab5.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\cb5b4c4a254fcdb0f0e4bfa876994975.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\e164747f3a6de906b6eb6827736607b2.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\7dd8282b269e23d6ea656e2291c34be2.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\44afdda4ed365ff344e7d157d852bb8d.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\4f8c82750eeb7b7e3392448ef8ed0362.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\1c46775bdf40f700f0e42f0ac42083d9.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\8eefb250052a9df110dab908cc1fa03a.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\installer.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\264d4ec686ac0113777f2a2576f69428.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\345cd209b3c2020151b56194e7964142.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\6c29e17da7495720874668a8ee15fcff.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\d897e087d31496699f5e2d6d4bd0793d.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\3691f47e94250aa261bae8be0c249902.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\099a922bf3e1009d299f7a2cc7067327.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\98370405397ce60f438e3acf43f7064c.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\67560ef530a06065794280f1f6997366.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\1ea8c619d0a377093604a8b7fa49e6a7.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\2aa587ee41994a5e6a07b92fe449acf1.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\c1ce9c865fb912fe84056ba2053b69c2.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\c7c9aa21663b70d765e1887317065d61.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\7d35ea2b5e647cebeedb345c5cd45916.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\104.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\button1.png
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\102.js
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins.json
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\manifest.xml
  • %APPDATA%\uaxtfe
  • %APPDATA%\uaxtfe.exe
  • %TEMP%\nsb4bff.tmp\7eac1701-e601-484f-8f22-d2e4387e8d8f-4.dll
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\button4.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\crossrider_statusbar.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\icon128.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\panelarrow-up.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\icon16.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\button3.png
  • %TEMP%\nsb4bff.tmp\{05f64033-d104-41ae-ac48-79a0368efa9d}\plugins\119.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\icon24.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\skin.css
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\button5.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\button2.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\update.css
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\popup.html
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\skin\icon48.png
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\018b29a0bf5d98b9cb1f1a090e14d865.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\b9c883b00660dee3fc3add8eac091f8e.js
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\api\0757877ad89a66dd4d78fed46eb3a8c0.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\178.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\252.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\14.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\123.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\104.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\179.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\231.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\4.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\281.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\242.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\91.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\93.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\267.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\221.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\286.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\123.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\popup.html
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\119.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\background.html
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\335.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\180.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\232.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\manifest.xml
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\manifest.json
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon128.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon16.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\actions\1.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon48.png
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\226.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\273.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\195.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\64.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\178.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\usercode\extension.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\13.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\47.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\17.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\78.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\102.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\288.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\80.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\184.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\223.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\usercode\background.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\19.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\292.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\220.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\262.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\246.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\315.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\289.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\260.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\263.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\14.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\104.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\9.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\97.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\chromecorefilesindex.txt
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\5058c703860ab496ad7718e9461c2712.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\settings.json
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdate.exe
  • %TEMP%\comh.11251\psuser.dll
  • %TEMP%\comh.11251\psmachine.dll
  • %TEMP%\comh.11251\npgoogleupdate4.dll
  • %TEMP%\comh.11251\goopdateres_en.dll
  • %TEMP%\comh.11251\goopdate.dll
  • %TEMP%\comh.11251\googleupdateondemand.exe
  • %TEMP%\comh.11251\googleupdatehelper.msi
  • %TEMP%\comh.11251\googleupdatebroker.exe
  • %TEMP%\comh.11251\googleupdate.exe
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\3e21f702-57c7-4f17-ba95-6ef6f69d19ab.crx
  • %TEMP%\comh.11251\googlecrashhandler.exe
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\uninstall.exe
  • %TEMP%\nsb4bff.tmp\77238
  • %TEMP%\nsb4bff.tmp\210610
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\utils.exe
  • %TEMP%\nsb4bff.tmp\md5dll.dll
  • %TEMP%\nsb4bff.tmp\nsisos.dll
  • %TEMP%\nsb4bff.tmp\userinfo.dll
  • %TEMP%\nsb4bff.tmp\installerutils2.dll
  • %TEMP%\nsb4bff.tmp\installerutils.dll
  • %TEMP%\nsb4bff.tmp\system.dll
  • %TEMP%\nsb4bff.tmp\stdutils.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-10.exe
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-3.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\goopdate.dll
  • %TEMP%\nsb4bff.tmp\execdos.dll
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\da425d78d8e2593e32c912a53d27c8d6.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\3d56481587394ba2b74c1f2b34c21b2b.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\2a3b33dd4f72660466c34ab209f51fbf.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\pageaction.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\40d2d0d3b31f5756a8e9fdc1c51dafad.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\9122a97fc33b1fdd7e41a7e357dec00f.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\fc1e67f3e0249d89c8ac0a453dc839a9.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\056d76e33a589563a5ecb7e670932ef2.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\4de9842282a67d00b864f7099e454e54.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\300139b976b32a1abee80352fdae1cd6.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\04cd7ff126e6d195efea0026873d70ae.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\installer.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\a9731928f7b2ad25d831ac21ffcc543b.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\50149c52272bd7cd3e01b56c83395e11.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\3607793279f4a37569a43a06d81fc4ac.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\aef47ec79ea1b1b844a52352e440e690.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\app_api.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\6478e93428b331c91b476b47c4098244.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\ad6af6ba2c343339fc527c58ae14a1b8.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\8715c40bfd2fbeaaa5e1bfb7f104031d.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\b9ff30cfef0d8451e3eb8aee29c82f55.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\1881e3d0ae0b3f3e6f512c1c45d13680.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\popupresource\newpopup.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\popupresource\popup.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\b3f32dcf1f726e98c039301228c44c55.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\main.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\hdtubev1.6v01.12-bho64.dll
  • %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\extensions\cufcv96103896@vlcz37079202.com\chrome\content\core\3a86ddbc82760d65c62931b0d83362cb.js
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googlecrashhandler.exe
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\6af4b6d1-d2a5-468d-9642-b735312ba64a.crx
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\179.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\220.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\262.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\246.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\315.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\289.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\260.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\263.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\14.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\104.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\9.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\97.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\292.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\195.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\119.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\7.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\231.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\4.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\281.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\242.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\91.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\93.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\267.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\221.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\19.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\286.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\178.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\223.js
  • %LOCALAPPDATA%\google\chrome\user data\default\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\7.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins\102.js
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\plugins.json
  • %TEMP%\nsb4bff.tmp\{c97e3194-217f-480d-93dc-3be449e06d9f}\manifest.xml
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\bgnova.html
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\websocket4net.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\supersocket.clientengine.protocol.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\supersocket.clientengine.core.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\supersocket.clientengine.common.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\newtonsoft.json.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\interop.iwshruntimelibrary.dll
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\settings.json
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\8057d7e2-a1f7-4357-b3b0-1e903d796636.exe
  • %TEMP%\nsb4bff.tmp\7eac1701-e601-484f-8f22-d2e4387e8d8f-11.dll
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\usercode\background.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\usercode\extension.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\13.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\47.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\17.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\78.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\102.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\288.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\80.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\184.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\64.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\123.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\273.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\226.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f.crx
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\ad6af6ba2c343339fc527c58ae14a1b8.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\8715c40bfd2fbeaaa5e1bfb7f104031d.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\b9ff30cfef0d8451e3eb8aee29c82f55.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\1881e3d0ae0b3f3e6f512c1c45d13680.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\popupresource\newpopup.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\popupresource\popup.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\b3f32dcf1f726e98c039301228c44c55.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\main.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\3607793279f4a37569a43a06d81fc4ac.js
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-11.exe
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\6478e93428b331c91b476b47c4098244.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\app_api.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\aef47ec79ea1b1b844a52352e440e690.js
  • %APPDATA%\vrlgqc
  • %APPDATA%\vrlgqc.exe
  • %TEMP%\nsb4bff.tmp\7eac1701-e601-484f-8f22-d2e4387e8d8f-3.dll
  • %TEMP%\msidbdd.log
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdateondemand.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdatebroker.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\npgoogleupdate4.dll
  • %ProgramFiles(x86)%\globalupdate\update\googleupdate.exe
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\psmachine.dll
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\psuser.dll
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\1293297481.mxaddon
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\50149c52272bd7cd3e01b56c83395e11.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\180.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\a9731928f7b2ad25d831ac21ffcc543b.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\335.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\5058c703860ab496ad7718e9461c2712.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins\232.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\manifest.xml
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\extensiondata\plugins.json
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\manifest.json
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon128.png
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon16.png
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\actions\1.png
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\icons\icon48.png
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\background.html
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\chromecorefilesindex.txt
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\popup.html
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\da425d78d8e2593e32c912a53d27c8d6.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\3d56481587394ba2b74c1f2b34c21b2b.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\2a3b33dd4f72660466c34ab209f51fbf.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\pageaction.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\40d2d0d3b31f5756a8e9fdc1c51dafad.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\api\9122a97fc33b1fdd7e41a7e357dec00f.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\fc1e67f3e0249d89c8ac0a453dc839a9.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\056d76e33a589563a5ecb7e670932ef2.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\4de9842282a67d00b864f7099e454e54.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\300139b976b32a1abee80352fdae1cd6.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\04cd7ff126e6d195efea0026873d70ae.js
  • %APPDATA%\opera software\opera stable\extensions\ofaemmlijemfcopjandkcndefpnacabg\1.26.83_0\js\lib\installer.js
  • %ProgramFiles(x86)%\globalupdate\update\1.3.25.0\googleupdatehelper.msi
  • %ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-2.exe
Deletes the following files
  • %TEMP%\nsb4bff.tmp\77238
  • %WINDIR%\tasks\temp_8057d7e2-a1f7-4357-b3b0-1e903d796636.job
  • <SYSTEM32>\tasks\temp_8057d7e2-a1f7-4357-b3b0-1e903d796636
  • %WINDIR%\tasks\temp_7eac1701-e601-484f-8f22-d2e4387e8d8f-6.job
  • <SYSTEM32>\tasks\temp_7eac1701-e601-484f-8f22-d2e4387e8d8f-6
  • %APPDATA%\microsoft\windows\cookies\user@newstaticclientstack[2].txt
  • %APPDATA%\microsoft\windows\cookies\user@newstaticclientstack[1].txt
Moves the following files
  • from %ProgramFiles(x86)%\hdtubev1.6v01.12\3e21f702-57c7-4f17-ba95-6ef6f69d19ab.dll to %ProgramFiles(x86)%\hdtubev1.6v01.12\3e21f702-57c7-4f17-ba95-6ef6f69d19ab.dll
Substitutes the following files
  • %TEMP%\nsb4bff.tmp\77238
  • %LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies-journal
  • %APPDATA%\Opera Software\Opera Stable\Cookies-journal
Network activity
TCP
HTTP GET requests
  • http://st###.###staticclientstack.com/installer.gif?ac###########################################################################################################################################...
  • http://lo##.####taticclientstack.com/monetization.gif?ev#########################################################################################################################################...
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
  • http://er####.##wstaticclientstack.com/ch-agent-error.gif?ac#####################################################################################################################################...
  • http://up####.##wstaticclientstack.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?ra######
  • http://up####.##wstaticclientstack.com/omaha/D3498EB0-CEF2-4D31-825C-888294AAA97F/1/update.xml?ra################################################################################################...
  • http://up####.##wstaticclientstack.com/omaha/D3498EB0-CEF2-4D31-825C-888294AAA97F/1/update.xml?ra######
  • http://lo##.####taticclientstack.com/monetization.gif?ra#########################################################################################################################################...
  • http://up####.##wstaticclientstack.com/omaha/D3498EB0-CEF2-4D31-825C-888294AAA97F/1/ping.xml?ra######
  • http://up####.##wstaticclientstack.com/omaha/D3498EB0-CEF2-4D31-825C-888294AAA97F/1/ping.xml?ra#######
  • http://js.#####aticclientstack.com/plugin/apps/61768/manifest/1_35_11_26/nova/manifest.xml?ve#############
  • http://st###.###staticclientstack.com/stats.gif?ac###############################################################################################################################################...
  • http://st###.###staticclientstack.com/apps.gif?ac################################################################################################################################################...
  • http://js.#####aticclientstack.com/plugin/apps/61768/manifest/1_35_11_26/ie8/manifest.xml?ve#############
  • http://js.####ntdemocloud.com/plugin/apps/61768/manifest/1_35_11_26/ie8/manifest.xml?ve#############
  • 'go###eapis.com':443
  • UDP
    • DNS ASK st###.###staticclientstack.com
    • DNS ASK lo##.####taticclientstack.com
    • DNS ASK go###eapis.com
    • DNS ASK microsoft.com
    • DNS ASK er####.##wstaticclientstack.com
    • DNS ASK up####.##wstaticclientstack.com
    • DNS ASK js.#####aticclientstack.com
    • DNS ASK js.####ntdemocloud.com
    Miscellaneous
    Searches for the following windows
    • ClassName: 'MS_AutodialMonitor' WindowName: ''
    • ClassName: 'MS_WebCheckMonitor' WindowName: ''
    Creates and executes the following
    • '%TEMP%\comh.11251\googleupdate.exe' /silent /install "appguid={d3498eb0-cef2-4d31-825c-888294aaa97f}&appname=6c778170-408f-4342-a935-3bfcafc911a6&needsadmin=True&lang=en"
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-6.exe' /rawdata=ryp4T0xqp/KB1dMbs2RZP6+aw61vZ8OfLqBE4YVNrjDmPqS4Bv6FQDTNxxL+wIR9yR0CJbeP9D7Kqcfs5h5Ac8Ekc4yP5zt64MFKQDAibi+wYZwooZ8VvfaOTCZr9hykfJEJGsJGEaQO9V3bk2O3WJ6Ygvc17vummhKkfQbOHGQTt/BsC+keoyVT...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.exe' /rawdata=SGplJOOkNdB49kjZwVHzfuwx7y+VUQPAd21Pt7et+822Kt3KknxXO+3nM6AHLI8gnoYdT2sauRhK/VXhhRpiuXWcNx0AXPwd3+TdzafnRQ8a71Q6ab0M8vTHzQFrWQXTC9kXBOKerbY3bVcC8sYE3bB+0VpcVRDQhC+Q9l02kEGodWKBag+RhBEk...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.exe' /rawdata=u/nAU2/9p+vIgKj6BtGjLAYYJoCx6t1CUG6B9gaHVGBjydSelX5dLQ+3OzRqxGz+O8QU6He0a2RFyVJA7SPZ0AAW/O++w5Q+tnp/YRqhgsNs1rVCAEyMeXku6tTcRc9wbouLRMWFotGQxVJOJ0edcWlsJDPfUaQqOXzb1gHLJed41MISUIkxqQpI...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-2.exe' /rawdata=Tod7olfPcmFE2J9w7w7Kbx/0psJ5IDXTZeurhOAz0gmzcTdeTU+LlwsSGnVolVQvh0WQWbvRyF33iBy8MNGu9EZyQQjMYCoc6dzqq0dTLjyJL5VuOmp4e7oX6VP+f7gRjt4ui9AY2kg72HQttrb61CV17z86NsZNjKgGRPEBzdgnq55X6r5Kdisf...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\8057d7e2-a1f7-4357-b3b0-1e903d796636.exe' 001695 A1688D6648474412A93CCAAA475B9E97IE 61768 1602989263 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HDtubeV1.6V01.12
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /svc
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-11.exe' /rawdata=GihvJGg3qfsi8VPWk/+wMy58ulIFHeUDPIKVbNaTyxPCQhr6plo6ehB2q8xoFLWlflLIas3RKKMXtsG/3zheoPmKxY6RcwxlBxk/pwLDOJQNaXzLYCBNMPZAALfYPLAbtYmRXbB+nlbtT8UZfFcD6aewJw0JhjHqQu+rC0wXKbi3yz2nP+Teu4wD...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /handoff "appguid={d3498eb0-cef2-4d31-825c-888294aaa97f}&appname=6c778170-408f-4342-a935-3bfcafc911a6&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{14F9E015-6877-4344-983...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsxNEY5RTAxNS02ODc3LTQzNDQtOTgzNS1FNkJBQTNGMDI...
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /regserver
    • '%ProgramFiles(x86)%\globalupdate\update\googleupdate.exe' /regsvc
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-3.exe' /rawdata=cEKxcfcVXoxUy8EW9GjIcAG/FBLwfY16dbKiNKlVKmxwYB0vVMCFb65JvZm2kEiNsLAHAKD6Zy05Cd/jPNMR+zv8u0tlKwmggIVnzsE4dlCY5jceclJFibR/dcnH4m26fZWTixysBrZ1wc14OwPrw1Q7p7pz4cl2Lx6dLDKeEyeDC+Ym2EMyVT0h...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-4.exe' /rawdata=HFWjf4DqniciSg7LkmRkcNr1TfdGAlNP5kz/kqXKpVNHEk5gVjS3u4Wp2ex5PoUBGPd4Ku9NjHwkc+c8QWnQV9KCi/+1PuMOWThtbiyllL1Oh4abLXnCd0j3TOYValkGOemdBJlyh1Zmp9NgG2r4nFiyk5brSO8tl+977Qza30S3VTkUSAQKUzdl...
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-6.exe' /rawdata=ryp4T0xqp/KB1dMbs2RZP6+aw61vZ8OfLqBE4YVNrjDmPqS4Bv6FQDTNxxL+wIR9yR0CJbeP9D7Kqcfs5h5Ac8Ekc4yP5zt64MFKQDAibi+wYZwooZ8VvfaOTCZr9hykfJEJGsJGEaQO9V3bk2O3WJ6Ygvc17vummhKkfQbOHGQTt/BsC+keoyVT...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-4.exe' /rawdata=HFWjf4DqniciSg7LkmRkcNr1TfdGAlNP5kz/kqXKpVNHEk5gVjS3u4Wp2ex5PoUBGPd4Ku9NjHwkc+c8QWnQV9KCi/+1PuMOWThtbiyllL1Oh4abLXnCd0j3TOYValkGOemdBJlyh1Zmp9NgG2r4nFiyk5brSO8tl+977Qza30S3VTkUSAQKUzdl...' (with hidden window)
    • '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\HDtubeV1.6V01.12\HDtubeV1.6V01.12-bho64.dll"' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\hdtubev1.6v01.12-codedownloader.exe' /rawdata=w48bWroAPLPzqXaNRrMlo4TZ2J5EL3HtVf0GQqfOUlOdrZjKHhICGReowKq3fuUr9s2zro8qQhdzzyqe8EGHIoPkzo2nQeeH5Qlfu/vRTFBuWOZd+VluXzY4cKPHCZdiFMD2SPMPlzIcSArp3Teeni+JTN9L+KR/HdV22/BWhtEKLMu1G3thYEdG...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-2.exe' /rawdata=Tod7olfPcmFE2J9w7w7Kbx/0psJ5IDXTZeurhOAz0gmzcTdeTU+LlwsSGnVolVQvh0WQWbvRyF33iBy8MNGu9EZyQQjMYCoc6dzqq0dTLjyJL5VuOmp4e7oX6VP+f7gRjt4ui9AY2kg72HQttrb61CV17z86NsZNjKgGRPEBzdgnq55X6r5Kdisf...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\hdtubev1.6v01.12-codedownloader.exe' /rawdata=Ia36PXc3f6RmFHQwLMs7dRBx3jYNRQ7nIv2dTX6ll+8iDhPY++XBU8zuhaXhOrbNWfUlym1hOGr6oqKIT3mQq+jpmK6bhu0r83syi2AlLlDzbheNB3htxaD4GGDy068HYUI+9OPaUN7Ei0DT+qIek8tO1NzlXERog9Oe+xdI91iA7BY+8BzNOxtk...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.exe' /rawdata=SGplJOOkNdB49kjZwVHzfuwx7y+VUQPAd21Pt7et+822Kt3KknxXO+3nM6AHLI8gnoYdT2sauRhK/VXhhRpiuXWcNx0AXPwd3+TdzafnRQ8a71Q6ab0M8vTHzQFrWQXTC9kXBOKerbY3bVcC8sYE3bB+0VpcVRDQhC+Q9l02kEGodWKBag+RhBEk...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\8057d7e2-a1f7-4357-b3b0-1e903d796636.exe' 001695 A1688D6648474412A93CCAAA475B9E97IE 61768 1602989263 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HDtubeV1.6V01.12' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-11.exe' /rawdata=GihvJGg3qfsi8VPWk/+wMy58ulIFHeUDPIKVbNaTyxPCQhr6plo6ehB2q8xoFLWlflLIas3RKKMXtsG/3zheoPmKxY6RcwxlBxk/pwLDOJQNaXzLYCBNMPZAALfYPLAbtYmRXbB+nlbtT8UZfFcD6aewJw0JhjHqQu+rC0wXKbi3yz2nP+Teu4wD...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-3.exe' /rawdata=cEKxcfcVXoxUy8EW9GjIcAG/FBLwfY16dbKiNKlVKmxwYB0vVMCFb65JvZm2kEiNsLAHAKD6Zy05Cd/jPNMR+zv8u0tlKwmggIVnzsE4dlCY5jceclJFibR/dcnH4m26fZWTixysBrZ1wc14OwPrw1Q7p7pz4cl2Lx6dLDKeEyeDC+Ym2EMyVT0h...' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\7eac1701-e601-484f-8f22-d2e4387e8d8f-7.exe' /rawdata=u/nAU2/9p+vIgKj6BtGjLAYYJoCx6t1CUG6B9gaHVGBjydSelX5dLQ+3OzRqxGz+O8QU6He0a2RFyVJA7SPZ0AAW/O++w5Q+tnp/YRqhgsNs1rVCAEyMeXku6tTcRc9wbouLRMWFotGQxVJOJ0edcWlsJDPfUaQqOXzb1gHLJed41MISUIkxqQpI...' (with hidden window)
    • '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\HDtubeV1.6V01.12\HDtubeV1.6V01.12-bho.dll"' (with hidden window)
    • '%ProgramFiles(x86)%\hdtubev1.6v01.12\hdtubev1.6v01.12-bg.exe' /executebg /externallog='%TEMP%\HDtubeV1.6V01.12Installer_1602989263.log'' (with hidden window)
    Executes the following
    • '<SYSTEM32>\taskeng.exe' {538FBB5F-BC6B-4646-9F30-07464BCEC9A5} S-1-5-21-1960123792-2022915161-3775307078-1001:enojsa\user:Interactive:[1]
    • '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\HDtubeV1.6V01.12\HDtubeV1.6V01.12-bho.dll"
    • '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\HDtubeV1.6V01.12\HDtubeV1.6V01.12-bho64.dll"
    • '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\HDtubeV1.6V01.12\HDtubeV1.6V01.12-bho64.dll"

    Recommandations pour le traitement

    1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
    2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

    Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

    Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

    1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
    2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
      • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
      • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
      • Débranchez votre appareil et rebranchez-le.

    En savoir plus sur Dr.Web pour Android